GoldenSpy

S0493

Malware.View on attack.mitre.org

About this malware

GoldenSpy is a backdoor malware which has been packaged with legitimate tax preparation software. GoldenSpy was discovered targeting organizations in China, being delivered with the "Intelligent Tax" software suite which is produced by the Golden Tax Department of Aisino Credit Information Co. and required to pay local taxes.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

GoldenSpy's uninstaller has base64-encoded its variables.

T1036.005
Match Legitimate Resource Name or Location

GoldenSpy's setup file installs initial executables under the folder %WinDir%\System32\PluginManager.

T1041
Exfiltration Over C2 Channel

GoldenSpy has exfiltrated host environment information to an external C2 domain via port 9006.

T1059.003
Windows Command Shell

GoldenSpy can execute remote commands via the command-line interface.

T1070.004
File Deletion

GoldenSpy's uninstaller can delete registry entries, files and folders, and finally itself once these tasks have been completed.

T1071.001
Web Protocols

GoldenSpy has used the Ryeol HTTP Client to facilitate HTTP internet communication.

T1082
System Information Discovery

GoldenSpy has gathered operating system information.

T1083
File and Directory Discovery

GoldenSpy has included a program "ExeProtector", which monitors for the existence of GoldenSpy on the infected system and redownloads if necessary.

T1105
Ingress Tool Transfer

GoldenSpy constantly attempts to download and execute files from the remote C2, including GoldenSpy itself if not found on the system.

T1106
Native API

GoldenSpy can execute remote commands in the Windows command shell using the WinExec() API.

T1136.001
Local Account

GoldenSpy can create new users on an infected system.

T1195.002
Compromise Software Supply Chain

GoldenSpy has been packaged with a legitimate tax preparation software.

T1497.003
Time Based Checks

GoldenSpy's installer has delayed installation of GoldenSpy for two hours after it reaches a victim system.

T1543.003
Windows Service

GoldenSpy has established persistence by running in the background as an autostart service.

T1571
Non-Standard Port

GoldenSpy has used HTTP over ports 9005 and 9006 for network traffic, 9002 for C2 requests, 33666 as a WebSocket, and 8090 to download files.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Trustwave GoldenSpy June 2020 Open source
    Trustwave SpiderLabs. (2020, June 25). The Golden Tax Department and Emergence of GoldenSpy Malware. Retrieved July 23, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.